logoalt Hacker News

lapcat • today at 2:06 PM • 3 replies • view on HN

> We can disable SIP

But this eliminates all SIP protections, for example, as discussed in the article, preventing Meta Muse from reading your Messages db.

Muse doesn't need Full Disk Access if SIP is disabled.


Replies

brigade • today at 2:36 PM

Which system integrity protection are you worried about missing? Muse being able to exfiltrate the contents of your messages db doesn’t compromise system integrity to begin with. It being able to write arguably does, but this whole conversation was about how to grant it full disk access in the future anyway.

And OP had SIP enabled, but his system still got compromised with a remote exploit.

➕ show 2 replies
john_alan • today at 4:27 PM

What about all the stuff they've done to keep it open:

- Per-install boot security policies

- Custom kernel boot (kmutil configure-boot)

- Raw-image boot mode

- XNU source releases

- Disabling SIP

- Disabling the Signed System Volume

- Third-party kernel extensions

- Developer ID distribution and notarisation

- Gatekeeper "Open Anyway" override

- Hypervisor.framework

- Virtualization.framework

- Rosetta for Linux VMs

- Nested virtualisation

- macOS guest provisioning

- DiskImageKit

- Custom Virtio devices

- Containerization framework

➕ show 1 reply